<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Headroom (&lt; 0.35.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/headroom--0.35.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 04:50:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/headroom--0.35.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cross-Site WebSocket Hijacking in Headroom</title><link>https://feed.craftedsignal.io/briefs/2026-10-headroom-cswsh/</link><pubDate>Sat, 03 Oct 2026 04:50:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-headroom-cswsh/</guid><description>The Headroom WebSocket server lacks Origin header validation, enabling Cross-Site WebSocket Hijacking that allows unauthorized parties to perform LLM requests via an injected OpenAI API key.</description><content:encoded><![CDATA[<p>The Headroom WebSocket server (pip package <code>headroom-ai</code> version &lt; 0.35.0) is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) due to a failure to validate the <code>Origin</code> header during the initial WebSocket handshake. By default, the Headroom proxy is configured to facilitate LLM interactions and will automatically inject the <code>OPENAI_API_KEY</code> environment variable into the <code>Authorization</code> header of outgoing requests if the client fails to provide one.</p>
<p>An attacker can host a malicious webpage that, when visited by a user or headless browser with internal network access to the Headroom proxy, initiates an unauthorized WebSocket connection to <code>ws://&lt;headroom_host&gt;:8787/v1/responses</code>. Once established, the attacker can submit arbitrary prompts or tool instructions - such as local shell execution requests - which the proxy will authenticate using the environment-stored API key. This flaw enables unauthenticated remote command execution (RCE) via the proxy's tool-calling capabilities and can result in significant financial loss through quota exhaustion.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies an accessible instance of a Headroom proxy on an internal network.</li>
<li>Attacker hosts a malicious webpage containing a WebSocket client targeting the Headroom proxy at <code>/v1/responses</code>.</li>
<li>A user within the network visits the malicious webpage via a web browser or a headless browser (e.g., lightpanda).</li>
<li>The browser initiates a WebSocket upgrade request to the Headroom proxy; the proxy fails to validate the <code>Origin</code> header of the request.</li>
<li>The proxy accepts the malicious connection and creates a WebSocket bridge.</li>
<li>The attacker sends a <code>response.create</code> JSON payload over the socket, including a tool execution command (e.g., <code>type: &quot;shell&quot;</code>).</li>
<li>Headroom observes the missing <code>Authorization</code> header, retrieves the <code>OPENAI_API_KEY</code> from the environment, and injects it into the upstream request to OpenAI.</li>
<li>The upstream OpenAI API executes the requested tool or prompt, returning the results or triggering RCE in the local environment if shell tools are enabled.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for unauthorized LLM model usage, potentially leading to the leakage of proprietary information or sensitive context. More critically, if shell tools or other system-level integrations are enabled in the Headroom configuration, the attacker can achieve remote command execution on the host machine. Furthermore, organizations face the risk of service disruption and financial impact due to the unauthorized consumption of OpenAI API quotas.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade <code>headroom-ai</code> to version 0.35.0 or later immediately to incorporate Origin header validation.</li>
<li>Implement network-level access control to restrict access to the Headroom proxy endpoint (<code>/v1/responses</code>) to trusted internal segments only.</li>
<li>Avoid storing <code>OPENAI_API_KEY</code> as a persistent environment variable on servers where the proxy is accessible by untrusted clients; utilize restricted IAM roles or transient credential stores if possible.</li>
<li>Monitor for unexpected WebSocket connections to the Headroom proxy port (default 8787) originating from client web browsers.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>